Trojan

Should I remove “Trojan.Win32.Cryprar.aed”?

Malware Removal

The Trojan.Win32.Cryprar.aed is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cryprar.aed virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Cryprar.aed?


File Info:

name: B0E64F3DA02FE0BAC510.mlw
path: /opt/CAPEv2/storage/binaries/dbc10a499e0c3bddcfa7266d5cce117343e0d8a164bdaa5d5dbcfee5d5392571
crc32: D35FC89A
md5: b0e64f3da02fe0bac5102fe4c0f65c32
sha1: eaf3e3cb39714a9fae0f1024f81a401aaf412436
sha256: dbc10a499e0c3bddcfa7266d5cce117343e0d8a164bdaa5d5dbcfee5d5392571
sha512: 579d4ba54a5a41cf2261360f0c009fd3e7b6990499e2366cb6f1eceacb2cc6215f053e780484908211b824711acbea389f3d91de6f40b9e2b6564baedd106805
ssdeep: 24576:IAOcZwXYYcCspN4GBlQ6EriuDbAPcOcUtvQ+I5hPjGqkKfIsAeaBhbHYVWRyX8B:m0vOKlQ658Oc6WBGqvfIsgBlYgB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123752301BAD584B2D6335935483CAB166A3D7D105E259F6FF3E4A86DEF314806338BA3
sha3_384: 2f76eeecb49e6457b0b7d791cad004485e0f4cfaf06fd4ee8391906acf71caa8087d9ef1854ebe8fd1e304ddc03f978e
ep_bytes: e89a040000e98efeffff3b0d68d64300
timestamp: 2020-03-26 10:02:47

Version Info:

0: [No Data]

Trojan.Win32.Cryprar.aed also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.Ciusky.Gen.6
FireEyeGeneric.mg.b0e64f3da02fe0ba
ALYacTrojan.Ciusky.Gen.6
CylanceUnsafe
SangforTrojan.Win32.Cryprar.aed
K7AntiVirusTrojan ( 00581bcf1 )
AlibabaTrojan:Win32/Cryprar.b8286e25
K7GWTrojan ( 00581bcf1 )
CyrenW32/S-536dd2d1!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32RAR/Agent.DQ
APEXMalicious
AvastSFX:Runner-C [Bd]
ClamAVWin.Dropper.Nanocore-9932569-0
KasperskyTrojan.Win32.Cryprar.aed
BitDefenderTrojan.Ciusky.Gen.6
NANO-AntivirusTrojan.Win32.Cryprar.jiztdk
TencentWin32.Trojan.Cryprar.Pfsw
Ad-AwareTrojan.Ciusky.Gen.6
EmsisoftTrojan.Ciusky.Gen.6 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
Paloaltogeneric.ml
GDataTrojan.Ciusky.Gen.6
WebrootW32.Trojan.FL
AviraTR/Agent.syqcq
eGambitUnsafe.AI_Score_94%
KingsoftWin32.Troj.Cryprar.a.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Ciusky.1564055
MicrosoftTrojan:Win32/Mamson.A!ac
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.C4851992
McAfeeArtemis!B0E64F3DA02F
VBA32Trojan.Cryprar
MalwarebytesTrojan.Dropper.SFX
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R002H0CLC21
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
AVGSFX:Runner-C [Bd]
Cybereasonmalicious.da02fe
PandaTrj/CI.A

How to remove Trojan.Win32.Cryprar.aed?

Trojan.Win32.Cryprar.aed removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment